AlejandroArciniegas mcp-data-vis MCP server.js request sql injection
Published Apr 2, 2026
6.9
MEDIUMCVSS 4.0
EPSS 0.41%
Description
A vulnerability has been found in AlejandroArciniegas mcp-data-vis bc597e391f184d2187062fd567599a3cb72adf51/de5a51525a69822290eaee569a1ab447b490746d. This affects the function Request of the file src/servers/database/server.js of the component MCP Handler. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
-
Affected
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| AlejandroArciniegas | Mcp-Data-Vis | unknown | Affected |
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-18126 Advisory
- https://github.com/wing3e/public_exp/issues/19 exploitissue-tracking
- https://vuldb.com/submit/780731 third-party-advisory
- https://vuldb.com/vuln/354654 vdb-entrytechnical-description
- https://vuldb.com/vuln/354654/cti signaturepermissions-required
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-18126 | Advisory | |
| https://github.com/wing3e/public_exp/issues/19 | exploitissue-tracking | |
| https://vuldb.com/submit/780731 | third-party-advisory | |
| https://vuldb.com/vuln/354654 | vdb-entrytechnical-description | |
| https://vuldb.com/vuln/354654/cti | signaturepermissions-required |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data